North Korea-aligned Andariel, a subgroup linked to Lazarus, conducted multiple intrusion campaigns against South Korean organizations across manufacturing, construction, education, defense, telecommunications, semiconductor, shipbuilding, electronics, and ICT sectors. Reporting from AhnLab ties the activity together through recurring victimology, repeated abuse of vulnerable or trusted enterprise software such as INNORIX Agent, domestic asset-management tools, software update mechanisms, and in one case an outdated Apache Tomcat web server. The campaigns also showed likely spearphishing, use of hidden accounts and scheduled tasks for persistence, and credential theft followed by lateral movement and remote desktop access.
The operators deployed an evolving malware set that included Goat RAT, AndarLoader, DurianBeacon, Nestdoor, Dora RAT, SmallTiger, TigerRat, NukeSped variants, Black RAT, Lilith RAT, and supporting tools such as PrintSpoofer, Mimikatz, ProcDump, Meterpreter, proxy utilities, keyloggers, clipboard stealers, and browser credential theft tools. AhnLab reported overlaps in command-and-control infrastructure and malware staging, including DurianBeacon delivering AndarLoader, SmallTiger fetching payloads in memory, and some Dora RAT samples being disguised as legitimate software like OpenVPN and signed with valid certificates. The activity reflects a continued shift in Andariel tooling while preserving long-standing tradecraft associated with Lazarus operations.

TTPs, infrastructure, and targeting history in one profile.
18 events from the most recent confirmed update back to the earliest known activity.
AhnLab Security Intelligence Center reported that Andariel used a malicious file to perform RID Hijacking during an intrusion, creating a hidden local account, modifying its SAM RID so Windows treated it as a privileged account, and preserving access while reducing account visibility. The report also compared the malware's behavior with the open-source CreateHiddenAccount tool and described use of PsExec to run the attack with SYSTEM privileges.
In May 2024, the actor shifted to using GitHub to distribute additional SmallTiger payloads. This marked a change in payload delivery infrastructure within the ongoing campaign.
In April 2024, the attacker used a downloader that invoked mshta to fetch malicious JavaScript from a command-and-control server. The script wrote a payload to an Alternate Data Stream and executed it with rundll32, resulting in SmallTiger execution.
From February 2024, ASEC observed the same actor resume attacks using another abused software product and a DLL downloader it named SmallTiger. SmallTiger downloaded payloads from command-and-control infrastructure and executed them in memory.
In early 2024, ASEC observed Nestdoor being distributed while masquerading as OpenVPN. Executing 'OpenVPN Installer.exe' caused a malicious DLL sideload chain that ultimately launched the Nestdoor payload 'openvpnsvc.exe'.
During the November 2023 phase of the campaign, ASEC observed the attackers using MultiRDP and Meterpreter on compromised systems. ASEC noted these tools and C2 similarities overlapped strongly with Kimsuky tradecraft.
ASEC first observed a campaign in November 2023 targeting South Korean defense, automotive parts, and semiconductor firms. In the initial case, the attackers laterally propagated malware via abused enterprise software update mechanisms and ultimately deployed an updated DurianBeacon backdoor.
In March 2023, Andariel reportedly targeted South Korean defense and electronics equipment companies. One attack chain used mshta.exe to install TigerRat, indicating script-based delivery and likely spearphishing.
ASEC previously disclosed that Andariel distributed malware to users of vulnerable INNORIX Agent versions 9.2.18.450 and earlier. The infections were found at multiple South Korean universities.
ASEC reported observing multiple attacks during 2023 in which Andariel prominently used Go-based malware. The campaigns targeted South Korean organizations across sectors including universities, defense, electronics, ICT, shipbuilding, and manufacturing.
ASEC observed Nestdoor in attacks together with TigerRAT in early 2023, with both malware families sharing the same command-and-control server. This linked Nestdoor more directly to established Andariel tooling.
In June 2022, CISA published analysis of attacks exploiting Log4Shell in VMware Horizon to install loader malware and an 'Unidentified RAT' with reverse shell, keylogging, clipboard logging, and proxy capabilities. ASEC later linked this tooling profile to Nestdoor-related activity.
ASEC says Nestdoor has been observed since at least May 2022 and has repeatedly appeared in Andariel attack cases as a remote access trojan used to control infected systems.
ASEC previously disclosed that Andariel exploited the VMware Horizon Log4Shell vulnerability CVE-2021-44228 to distribute TigerRAT. This established a documented Andariel use of Log4Shell for malware delivery.
ASEC states that the North Korea-aligned Andariel group has targeted organizations in South Korea since at least 2008, including sectors such as defense, politics, shipbuilding, energy, telecommunications, universities, transportation, and ICT.
In one directly confirmed intrusion from the Dora RAT campaign, attackers compromised a web server running a 2013-era Apache Tomcat installation and used it to distribute malware. After gaining access, they installed backdoors and proxy tools.
ASEC identified a recent Andariel APT campaign targeting South Korean manufacturing firms, construction companies, and educational institutions. The campaign used Nestdoor, the newly identified Go-based Dora RAT, keyloggers, infostealers, and proxy tools.
AhnLab published analysis of a recent Andariel campaign in South Korea that abused a domestic asset management program and also targeted poorly secured MS-SQL servers. The activity distributed TigerRat, NukeSped variants, Black RAT, a Go-based downloader, and Lilith RAT.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 53 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
7 references tracked. Mallory keeps watching after this page renders.
asec.ahnlab.com
Open sourceasec.ahnlab.com
Open sourceasec.ahnlab.com
Open sourceasec.ahnlab.com
Open sourceasec.ahnlab.com
Open sourcedownload.ahnlab.com
Open sourceblog.talosintelligence.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.